Splunk Search

XML epoch time to time

chevalier51
Loves-to-Learn Lots

I want to extract dailyTime from XML and convert it into time

 

 

<globalView id="108" version="17" recordClassName="NormalizedEvent" retention="0" hourly="-1" hourlyTime="1284336038994" daily="-1" dailyTime="1284336038994" intervalMilliseconds="60000" writeUniqueCountersTime="0">
        <criteria bop="AND">
          <left>
            <expr>
              <interval serialization="custom">
                <com.q1labs.ariel.Interval>
                  <short>5000</short>
                  <boolean>true</boolean>
                  <short>5000</short>
                  <boolean>true</boolean>
                </com.q1labs.ariel.Interval>
              </interval>
            </expr>
            <key class

 

 

Here is my props.conf

 

 

[XMLPARSING]
KV_MODE = xml
SHOULD_LINEMERGE = true
BREAK_ONLY_BEFORE = <globalView\s\w*=("\d\d\d")
MAX_EVENTS = 600 
EXTRACT-dailyTime = ^(?:[^=\n]*=){8}"(\d+)
TIME_FORMAT=%s%3N
TIME_PREFIX=dailyTime=
Lookahead=13
TRUNCATE = 1000
category = Custom
disabled = false
pulldown_type = true

 

 

but splunk is not converting it

Labels (3)
Tags (1)
0 Karma

ashajambagi
Communicator

Hey

try this
TIME_PREFIX=dailyTime\D+

 

0 Karma

chevalier51
Loves-to-Learn Lots

@ashajambagiNo not working

0 Karma

ashajambagi
Communicator

@chevalier51 Epoch converter shows the date to be 2010,try increasing the MAX_DAYS_AGO

 

TIME_FORMAT=%s%3N
TIME_PREFIX=dailyTime\D+
MAX_TIMESTAMP_LOOKAHEAD=13
MAX_DAYS_AGO=5000

 

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Try

TIME_PREFIX=dailyTime="
---
If this reply helps you, Karma would be appreciated.
0 Karma

chevalier51
Loves-to-Learn Lots

@richgalloway No not working

0 Karma

richgalloway
SplunkTrust
SplunkTrust
Did you restart the indexer/HF after changing props.conf? Are you checking new data? Changes to props.conf don't apply to data that's already indexed.
---
If this reply helps you, Karma would be appreciated.
0 Karma

chevalier51
Loves-to-Learn Lots

@richgallowayYes off course

 

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...